The ColdCard Hardware Wallet Attack
What happened (in simple terms), what you should do if affected, and what we can ALL learn from it.
What happened last week?
If you are in Bitcoin, and especially if you hold Bitcoin in self-custody, you should by now have heard about the Coldcard hardware wallet flaw that allowed millions of dollars to be drained from these wallets since last Thursday, July 30th.
Coldcard Mk3 models were primarily affected; however, it was later discovered that Mk4 and Q models were also at risk. Basically, any seed phrase generated by one of these wallets since 2021 should be considered compromised.
How was I affected?
I’ll start this by saying I had a Coldcard Q set up as my primary wallet. I woke up on Friday morning to a flurry of messages and social media activity around the issue. At that stage, it was definitely affecting the Mk3s, but I wasn’t certain if other models were affected.
When I checked, all my BTC was still there. I had set my Coldcard up with a passphrase (or 25th word), which makes it more difficult to breach with ‘brute force’, so I felt comfortable that I was in no immediate danger.
However, out of an abundance of caution, I decided to move my BTC holdings away from the Coldcard-generated seed phrase and set up a brand new seed phrase, using a different device (a Seedsigner).
What was the problem with Coldcards?
The problem that made any Bitcoin secured with a Coldcard vulnerable to ‘brute-force’ attacks was how the device generated the seed phrase.
To be clear - it was not the hardware itself that was compromised, but the seed phrases it produced.
To put it very simply, the Coldcards were supposed to generate a seed phrase using an RNG (Random Number Generator), but because of a code error, they weren't.
Instead, they were falling back upon creating seed phrases using a different method that was not nearly random enough.
Randomness in seed phrase generation is known as ‘entropy’, and when a seed phrase is generated with truly strong entropy, it is practically impossible to crack.
When it is created with weak entropy, it narrows down the options of what it could be, and thus it can be ‘guessed’.
In the case of Coldcard, the entropy was extremely weak, which essentially enabled reverse-engineering of the seed-generation process and thus narrowed the possible seed phrase options to the point where they could be guessed with powerful computers.
So the brute force attacks leading to the wallet drains had nothing to do with the actual physical device, whether it had ever been connected to the internet, how the user used it, a hack, or anything of this nature.
The attacks relied solely on weak entropy during seed phrase creation. That is to say, if you have ever imported a seed phrase generated in a Coldcard to another completely unrelated device, any Bitcoin secured by that particular seed phrase is still vulnerable to a brute force attack, regardless of the device.
Case in point - I had a secondary hardware wallet - a different brand - set up with my Coldcard-generated seed phrase. The purpose of this secondary wallet was to serve as a backup in case anything happened to my Coldcard - I would still have another device to access my BTC holdings.
Even though it was a different hardware wallet brand, any BTC secured with that wallet using the same seed phrase is still just as vulnerable to a brute-force attack. If I wanted to use that device as my main hardware wallet, the only option would have been to completely wipe it and start again with a new seed phrase.
So the main point here is: ANY Coldcard-generated seed phrase should be treated as potentially compromised, even if it has been imported to a different hardware device.
What you should do if affected by this
First, I hope anyone potentially affected by this has already been able to move their funds from their Coldcard to an alternative device. Time is of the essence, especially if you did not set up your Coldcard with a passphrase. If this is you, and you have not done so yet, then please act immediately.
The first step is to determine where you can send your BTC, so it is no longer secured by your Coldcard and thus not vulnerable to a brute-force attack.
The following are all options:
If you have access to another hardware device, set it up with a brand-new seed phrase and move your holdings to it. This is the best option if you already have an alternative device and you are comfortable setting it up from scratch. If you choose this option, make sure you back up your new seed phrase.
If you do not have access to another hardware device, you can move it to a self-custody software or hot wallet like Blue wallet, Aqua wallet, or a Sparrow wallet (remember, Sparrow is desktop only - there are no Sparrow mobile apps).
The last option is to move your funds to an exchange. This is best for people who just want to move BTC quickly and are not comfortable setting up another wallet immediately. Just remember that any BTC moved into and out of exchanges will be subject to KYC.
Once you have secured your BTC, you can then decide on your next course of action. If you chose options 2 or 3 above, these are only temporary solutions to secure your BTC in the interim. If you have used one of these options, you need to decide:
Will you wipe your existing Coldcard and set it up again with a new seed phrase? The firmware bug that caused the problem has been fixed, but understandably, many will not be willing to trust it now. If this is the case, you will need to use the dice-roll method (more on that later)
Will you get a brand-new device from another brand and set it up from scratch?
In either case, try to expedite the process as much as possible (without rushing) so you can get your BTC back into self-custody using a hardware device and a new, secure seed phrase.
Personally, I chose option 1 because I already had a Seedsigner and was comfortable setting it up from scratch with a brand-new seed phrase and passphrase, then transferring my BTC over. I then backed up my new seed phrase. My old Coldcard-generated seed phrase will never be used again.
Creating a strong seed phrase
So how can you ensure that proper entropy is applied when you set up a new seed phrase? As it turns out, both computers and humans are terrible at generating true entropy, so we need tools to help us do so in an objective, non-replicable manner.
I believe the number one thing most of us have taken from this Coldcard incident is: can we even trust the wallets themselves to generate our seed phrases?
For five years, we had been trusting that Coldcard’s seed generation was creating strong, unique, unreplicable seed phrases that could not be cracked. And as it turned out, we were wrong. So we were trusting, but not verifying.
The problem for most of us is that, without the knowledge and expertise to read and understand the code, we felt we had no option but to trust it.
In fact, there are ways of creating a seed phrase that don’t rely on the hardware wallet itself. I think that a vast majority of Bitcoiners did not realize this, or, if they did, dismissed this step as unnecessary.
Dice rolls
You may have already heard about this option. If you are setting up a brand new seed phrase, out of an abundance of caution, using the dice-roll method will create true entropy and produce a seed phrase that is not vulnerable to any brute-force attack.
How does it work? The basic premise is that you roll a die to generate a number from 1 to 6, which is then used as the source of entropy for the creation of your seed phrase.
Coldcard, BitBox02, Seedsigner, and Blockstream Jade wallets all allow you to use this option. (Other popular wallets may have this feature as well - you will need to check with the manufacturer to confirm.)
Note that each brand will vary in how this process actually works for their wallet.
Here is a 2025 video from ForrestHODL on creating a dice-roll seed phrase on a Coldcard:
But why go to all this trouble anyway? Because that means your seed phrase is created completely independently of the wallet, and you no longer need to trust the wallet’s RNG.
To be clear, there is no reason to think that this process is flawed in any way for other wallet brands, but the whole point is that most of us have no way of knowing for sure.
Photographic entropy
Another alternative to dice rolls is the entropy created by a photograph.
The Seedsigner has this option built into the device. I am unsure about other brands.
The way it works is - the internal camera on the Seedsigner can be used to photograph something. The data from that still image is then used to derive a seed phrase.
If you do use this option, take a photo of something with lots of detail that looks random and non-uniform. You can take a photo of anything - a messy room, trees and foliage, or cars going past on a road. Anything that is not uniform or replicable.
For this option, there is still some trust in the device itself, but you know it derives a seed from randomness rather than a predictable formula.
This BTCSessions video on Seedsigner shows a demonstration of this process:
The takeaways from this incident that we should ALL pay attention to!
Right now, the only people directly affected by this Coldcard flaw are people who generated a seed phrase from a Coldcard since 2021.
Many of you reading this will not own Coldcards, and you will not have any immediate consequences.
The thing about the Bitcoin world is that this is a relatively new technology, and things are changing and evolving rapidly.
We have entered an era in which the emergence of increasingly sophisticated AI is making it easier for bad actors to exploit flaws like this.
Without any expert knowledge on the topic, I would guess that this particular flaw could not have been uncovered and exploited without AI tools - at least not this quickly.
What this means is that if we hold Bitcoin in self-custody, it is a strong reminder to stay on top of our game.
Nobody is at fault for choosing to use a Coldcard and then subsequently losing their Bitcoin, or being put in a position where they are potentially vulnerable to losing it all.
But self-custody is something that must be practiced, and it evolves over time.
These are the main things that have become very apparent to me in the last few days:
Do not rely on a single seed phrase alone to secure your Bitcoin. In this incident, having a passphrase set up offered an extra level of protection, giving Coldcard users time to secure their funds.
While securing Bitcoin against brute-force attacks is not the primary purpose of a passphrase, it can still help if the seed phrase has been compromised. Just ensure your passphrase is not too short or easily guessable - make it at least 16 characters long and use a mix of different types of characters.Know how to access and move your Bitcoin. This is really important. You do NOT want to be trying to secure all your Bitcoin under duress when you feel like you have no clue what you are doing. You want to know how to do it without pressure. Practice making Bitcoin transactions using your hardware wallet frequently (at least once per month) - even if it’s just to send it to another wallet and then back.
I have seen many stories of people who had secured their Bitcoin with a Coldcard and then left it in a drawer for years. When this flaw was exposed, they had no idea how to operate their hardware wallet, which caused a. lot of stress and anxiety.Always have a backup hardware wallet and know how to use it. This incident has shown us that it is wise to have a backup wallet from a different brand than your primary wallet. Practice setting it up from scratch with a brand-new seed phrase at least once.
If you go on vacation, consider what would happen if you needed access to your Bitcoin while you are away. If you leave your hardware wallet at home, you will not be able to access it in an emergency. Unfortunately, this incident occurred at the height of the northern hemisphere summer, when many people had already left home for vacation.
Consider creating any new seed phrases using the 100-dice-roll or photographic entropy method from here on out.
Make sure you keep up-to-date with Bitcoin news - follow trusted YouTube channels, X accounts, or subscribe to newsletters. Time is of the essence when there is a potential emergency like this.
Should I just give up on self-custody?
Absolutely not.
There are some shrill voices in the space who are currently advocating for people to just give up on the idea of self-sovereignty altogether - it’s too hard, it’s too risky, it’s not for ordinary people. Instead, they say, entrust your Bitcoin to a third party or - worse - sell it all, buy IBIT, and trust Blackrock instead.
Others are saying this is a case for a multi-sig setup - one that involves a custodian.
I fundamentally disagree with all of this.
If you remain practiced in the art of self-custody, prepared to move your Bitcoin calmly and confidently if you should ever need to, and have lots of redundancy in place (in this case, for example, like extra hardware wallets) and know where to go for information when a potential crisis arises, there is absolutely no need to start involving ‘trusted’ third parties in your Bitcoin custody.
EVERY method of custody involves some type of risk, whether it be the risks of single-sig self-custody, the risks of multi-sig custody, the risks of trusting a custodian, or the risks of holding Wall Street-wrapped Bitcoin products.
For me, I prefer the risks I can control, even if it means more work on my part.
Don’t allow this instance of a hardware wallet flaw to scare you away from self-custody of your Bitcoin. What should scare you a lot more is the idea of trusting other parties to take care of your Bitcoin, because many more people have lost much more Bitcoin doing precisely this.
You may also like…
You're Still Here.
The most difficult time to be a creator or author in the world of Bitcoin is when the dollar price is bottoming out.
⛔️ DISCLAIMER: This content is for informational and entertainment purposes only and should not be considered financial, investment, or legal advice. I am not a licensed financial advisor, accountant, or investment professional. The information shared in this post reflects my personal opinions and is based on publicly available data at the time of writing. All investment decisions - especially those involving Bitcoin or other digital assets - carry risk and should be made only after conducting your own due diligence and consulting with a qualified financial advisor. Never invest more than you can afford to lose. This post may contain affiliate links that pay me a small commission - at no extra expense to you - if you click the link and purchase the product/service. My views are my own and do not reflect those of any of my affiliate partners or sponsors.





